First published: Fri Oct 12 2001(Updated: )
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Immunix | =6.2 | |
Immunix | =7.0 | |
Immunix | =7.0_beta | |
University of Washington PINE | <=4.33 | |
engardelinux secure linux | =1.0.1 | |
mandrakesoft mandrake linux | =7.1 | |
mandrakesoft mandrake linux | =7.2 | |
mandrakesoft mandrake linux | =8.0 | |
Mandriva Linux Corporate Server | =1.0.1 | |
redhat linux | =5.2 | |
redhat linux | =6.2 | |
redhat linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0736 is classified as a moderate severity vulnerability.
To fix CVE-2001-0736, upgrade to a patched version of pine or pico that addresses the symlink issue.
All versions of pine prior to 4.33 are affected by CVE-2001-0736.
CVE-2001-0736 allows local users to overwrite arbitrary files using a symlink attack due to improper handling of symlinks.
CVE-2001-0736 affects various versions of Immunix, Mandrake Linux, and Red Hat Linux that ship with vulnerable versions of pine.